Skip to main content
عربي
logo

NCSC-TAD-2606-001

Severity Level: High
Vulnerability

Reference No.: NCSC-TAD-2606-001CVSS 0

Microsoft Exchange Server XSS Vulnerability

Threat Type:
N/A
TLP:
CLEAR
CVE:
CVE-2026-42897

Overview

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Affected Technologies

  • Microsoft Exchange Outlook Web Access (OWA)

Mitigation and Immediate Actions

  1. 01

    Apply the latest Exchange Server security updates and maintain existing mitigations as an additional layer of defence.

  2. 02

    Exchange Emergency Mitigation (EM) Service: Block mitigation M2 from re-applying and remove the M2 IIS rules.

  3. 03

    EOMT script: Roll back the mitigation.

References